shopify-agent-discount

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s install sources are mostly same-org/offical, but its actual footprint is mismatched to its purpose: a Shopify discount checker should not normally require generating an Ethereum private key, storing it locally, and registering a wallet-backed agent. No confirmed credential theft is shown, yet the crypto-based auth flow, broad shell permissions, and credential forwarding to local code make the skill higher risk than its description implies.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:54 AM
Package URL
pkg:socket/skills-sh/worldcoin%2Fagentkit-shopify-demo%2Fshopify-agent-discount%2F@8793c5d2bec5ca3cbc458640fcc9be4d1d45f1f4